2017-09-25 14:01:22 +00:00
|
|
|
#!/usr/bin/env python3
|
2017-08-07 09:50:12 +00:00
|
|
|
|
|
|
|
from __future__ import print_function
|
|
|
|
|
2017-02-09 15:26:15 +00:00
|
|
|
import sys
|
|
|
|
import struct
|
|
|
|
import binascii
|
2017-03-22 00:53:25 +00:00
|
|
|
import pyblake2
|
2017-02-09 15:26:15 +00:00
|
|
|
|
2017-10-03 22:39:43 +00:00
|
|
|
from trezorlib import ed25519raw, ed25519cosi
|
2017-02-09 17:14:10 +00:00
|
|
|
|
2017-10-01 14:26:51 +00:00
|
|
|
|
2017-10-04 07:59:04 +00:00
|
|
|
if sys.version_info.major < 3:
|
|
|
|
input = raw_input
|
|
|
|
|
|
|
|
|
|
|
|
def get_trezor(index):
|
|
|
|
from trezorlib.client import TrezorClient
|
|
|
|
from trezorlib.transport_hid import HidTransport
|
|
|
|
devices = HidTransport.enumerate()
|
|
|
|
if len(devices) > index:
|
|
|
|
return TrezorClient(devices[index])
|
|
|
|
else:
|
|
|
|
raise Exception('TREZOR with such index not found')
|
|
|
|
|
|
|
|
|
2017-10-01 14:26:51 +00:00
|
|
|
def sign_data(seckeys, data):
|
2017-10-01 15:46:58 +00:00
|
|
|
digest = pyblake2.blake2s(data).digest()
|
2017-10-01 14:26:51 +00:00
|
|
|
if len(seckeys) == 1:
|
|
|
|
sk = seckeys[0]
|
|
|
|
pk = ed25519raw.publickey(sk)
|
|
|
|
return ed25519raw.signature(digest, sk, pk)
|
|
|
|
else:
|
2017-10-01 15:46:58 +00:00
|
|
|
ctr = 0
|
2017-10-04 07:59:04 +00:00
|
|
|
pubkeys = []
|
2017-10-01 15:46:58 +00:00
|
|
|
nonces = []
|
|
|
|
commits = []
|
2017-10-04 07:59:04 +00:00
|
|
|
for i, sk in enumerate(seckeys):
|
|
|
|
if sk == 'trezor':
|
|
|
|
t = get_trezor(i)
|
|
|
|
# FIXME: path below should change according to what is being signed
|
|
|
|
commit = t.cosi_commit(t.expand_path("10018'/0'"), digest)
|
|
|
|
pk = commit.pubkey
|
|
|
|
r = None
|
|
|
|
R = commit.commitment
|
|
|
|
else:
|
|
|
|
pk = ed25519raw.publickey(sk)
|
|
|
|
r, R = ed25519cosi.get_nonce(sk, digest, ctr)
|
|
|
|
pubkeys.append(pk)
|
2017-10-01 15:46:58 +00:00
|
|
|
nonces.append(r)
|
|
|
|
commits.append(R)
|
|
|
|
global_pk = ed25519cosi.combine_keys(pubkeys)
|
|
|
|
global_R = ed25519cosi.combine_keys(commits)
|
|
|
|
sigs = []
|
2017-10-04 07:59:04 +00:00
|
|
|
for i, sk in enumerate(seckeys):
|
|
|
|
if sk == 'trezor':
|
|
|
|
t = get_trezor(i)
|
|
|
|
# FIXME: path below should change according to what is being signed
|
|
|
|
signature = t.cosi_sign(t.expand_path("10018'/0'"), digest, global_R, global_pk)
|
|
|
|
sig = signature.signature
|
|
|
|
else:
|
|
|
|
r = nonces[i]
|
|
|
|
R = commits[i]
|
|
|
|
h = ed25519raw.H(sk)
|
|
|
|
b = ed25519raw.b
|
|
|
|
a = 2 ** (b - 2) + sum(2 ** i * ed25519raw.bit(h, i) for i in range(3, b - 2))
|
|
|
|
S = (r + ed25519raw.Hint(global_R + global_pk + digest) * a) % ed25519raw.l
|
|
|
|
sig = ed25519raw.encodeint(S)
|
|
|
|
sigs.append(sig)
|
2017-10-01 15:46:58 +00:00
|
|
|
sig = ed25519cosi.combine_sig(global_R, sigs)
|
|
|
|
ed25519raw.checkvalid(sig, digest, global_pk)
|
|
|
|
return sig
|
2017-02-09 15:26:15 +00:00
|
|
|
|
2017-09-05 21:15:47 +00:00
|
|
|
|
2017-04-06 16:57:51 +00:00
|
|
|
def format_sigmask(sigmask):
|
2017-09-05 21:15:47 +00:00
|
|
|
bits = [str(b + 1) if sigmask & (1 << b) else '.' for b in range(8)]
|
2017-04-06 16:57:51 +00:00
|
|
|
return '0x%02x = [%s]' % (sigmask, ' '.join(bits))
|
|
|
|
|
|
|
|
|
2017-04-10 17:24:21 +00:00
|
|
|
# bootloader/firmware headers specification: https://github.com/trezor/trezor-core/blob/master/docs/bootloader.md
|
2017-02-09 15:26:15 +00:00
|
|
|
|
2017-04-01 00:32:05 +00:00
|
|
|
|
2017-08-07 09:50:12 +00:00
|
|
|
class BinImage(object):
|
2017-04-01 00:32:05 +00:00
|
|
|
|
|
|
|
def __init__(self, data, magic, max_size):
|
2017-03-31 21:54:59 +00:00
|
|
|
header = struct.unpack('<4sIIIBBBB427sB64s', data[:512])
|
2017-03-30 20:58:00 +00:00
|
|
|
self.magic, \
|
|
|
|
self.hdrlen, \
|
|
|
|
self.expiry, \
|
|
|
|
self.codelen, \
|
|
|
|
self.vmajor, \
|
|
|
|
self.vminor, \
|
|
|
|
self.vpatch, \
|
|
|
|
self.vbuild, \
|
|
|
|
self.reserved, \
|
2017-04-01 00:32:05 +00:00
|
|
|
self.sigmask, \
|
2017-03-30 20:58:00 +00:00
|
|
|
self.sig = header
|
2017-04-01 00:32:05 +00:00
|
|
|
assert self.magic == magic
|
2017-03-31 21:54:59 +00:00
|
|
|
assert self.hdrlen == 512
|
2017-04-01 00:32:05 +00:00
|
|
|
total_len = self.hdrlen + self.codelen
|
|
|
|
assert total_len % 512 == 0
|
|
|
|
assert total_len >= 4 * 1024
|
|
|
|
assert total_len <= max_size
|
2017-03-31 21:54:59 +00:00
|
|
|
assert self.reserved == 427 * b'\x00'
|
2017-02-17 16:11:34 +00:00
|
|
|
self.code = data[self.hdrlen:]
|
2017-02-09 15:26:15 +00:00
|
|
|
assert len(self.code) == self.codelen
|
|
|
|
|
|
|
|
def print(self):
|
2017-04-01 00:32:05 +00:00
|
|
|
if self.magic == b'TRZF':
|
|
|
|
print('TREZOR Firmware Image')
|
2017-04-06 14:58:16 +00:00
|
|
|
total_len = self.vhdrlen + self.hdrlen + self.codelen
|
2017-04-10 17:24:21 +00:00
|
|
|
elif self.magic == b'TRZB':
|
|
|
|
print('TREZOR Bootloader Image')
|
2017-04-06 14:58:16 +00:00
|
|
|
total_len = self.hdrlen + self.codelen
|
2017-04-01 00:32:05 +00:00
|
|
|
else:
|
|
|
|
print('TREZOR Unknown Image')
|
2017-02-09 15:26:15 +00:00
|
|
|
print(' * magic :', self.magic.decode('ascii'))
|
|
|
|
print(' * hdrlen :', self.hdrlen)
|
|
|
|
print(' * expiry :', self.expiry)
|
|
|
|
print(' * codelen :', self.codelen)
|
|
|
|
print(' * version : %d.%d.%d.%d' % (self.vmajor, self.vminor, self.vpatch, self.vbuild))
|
2017-04-06 16:57:51 +00:00
|
|
|
print(' * sigmask :', format_sigmask(self.sigmask))
|
2017-02-09 15:26:15 +00:00
|
|
|
print(' * sig :', binascii.hexlify(self.sig).decode('ascii'))
|
2017-04-06 14:58:16 +00:00
|
|
|
print(' * total : %d bytes' % total_len)
|
|
|
|
print()
|
2017-02-09 15:26:15 +00:00
|
|
|
|
2017-03-30 20:58:00 +00:00
|
|
|
def serialize_header(self, sig=True):
|
2017-09-05 21:15:47 +00:00
|
|
|
header = struct.pack('<4sIIIBBBB427s',
|
|
|
|
self.magic, self.hdrlen, self.expiry, self.codelen,
|
|
|
|
self.vmajor, self.vminor, self.vpatch, self.vbuild,
|
|
|
|
self.reserved)
|
2017-02-09 15:26:15 +00:00
|
|
|
if sig:
|
2017-04-01 00:32:05 +00:00
|
|
|
header += struct.pack('<B64s', self.sigmask, self.sig)
|
2017-02-09 15:26:15 +00:00
|
|
|
else:
|
|
|
|
header += 65 * b'\x00'
|
2017-02-17 16:11:34 +00:00
|
|
|
assert len(header) == self.hdrlen
|
2017-02-09 15:26:15 +00:00
|
|
|
return header
|
|
|
|
|
2017-10-01 14:26:51 +00:00
|
|
|
def sign(self, sigmask, seckeys):
|
2017-03-30 20:58:00 +00:00
|
|
|
header = self.serialize_header(sig=False)
|
2017-02-09 15:26:15 +00:00
|
|
|
data = header + self.code
|
2017-02-17 16:11:34 +00:00
|
|
|
assert len(data) == self.hdrlen + self.codelen
|
2017-04-08 16:23:08 +00:00
|
|
|
self.sigmask = sigmask
|
2017-10-01 14:26:51 +00:00
|
|
|
self.sig = sign_data(seckeys, data)
|
2017-02-09 15:26:15 +00:00
|
|
|
|
|
|
|
def write(self, filename):
|
|
|
|
with open(filename, 'wb') as f:
|
2017-03-30 20:58:00 +00:00
|
|
|
f.write(self.serialize_header())
|
2017-02-09 15:26:15 +00:00
|
|
|
f.write(self.code)
|
|
|
|
|
|
|
|
|
2017-04-01 00:32:05 +00:00
|
|
|
class FirmwareImage(BinImage):
|
|
|
|
|
2017-04-01 13:45:50 +00:00
|
|
|
def __init__(self, data, vhdrlen):
|
2017-09-05 21:15:47 +00:00
|
|
|
super(FirmwareImage, self).__init__(data[vhdrlen:], magic=b'TRZF', max_size=7 * 128 * 1024)
|
2017-04-06 14:58:16 +00:00
|
|
|
self.vhdrlen = vhdrlen
|
|
|
|
self.vheader = data[:vhdrlen]
|
2017-04-01 00:32:05 +00:00
|
|
|
|
2017-04-01 13:45:50 +00:00
|
|
|
def write(self, filename):
|
|
|
|
with open(filename, 'wb') as f:
|
|
|
|
f.write(self.vheader)
|
|
|
|
f.write(self.serialize_header())
|
|
|
|
f.write(self.code)
|
2017-04-01 00:32:05 +00:00
|
|
|
|
2017-09-05 21:15:47 +00:00
|
|
|
|
2017-04-10 17:24:21 +00:00
|
|
|
class BootloaderImage(BinImage):
|
2017-04-01 00:32:05 +00:00
|
|
|
|
|
|
|
def __init__(self, data):
|
2017-09-05 21:15:47 +00:00
|
|
|
super(BootloaderImage, self).__init__(data, magic=b'TRZB', max_size=64 * 1024 + 7 * 128 * 1024)
|
2017-04-01 00:32:05 +00:00
|
|
|
|
|
|
|
|
2017-08-07 09:50:12 +00:00
|
|
|
class VendorHeader(object):
|
2017-02-09 15:26:15 +00:00
|
|
|
|
|
|
|
def __init__(self, data):
|
2017-10-05 15:31:05 +00:00
|
|
|
header = struct.unpack('<4sIIBBBBB', data[:17])
|
2017-03-30 20:58:00 +00:00
|
|
|
self.magic, \
|
|
|
|
self.hdrlen, \
|
|
|
|
self.expiry, \
|
|
|
|
self.vmajor, \
|
|
|
|
self.vminor, \
|
|
|
|
self.vsig_m, \
|
2017-10-05 15:31:05 +00:00
|
|
|
self.vsig_n, \
|
|
|
|
self.vtrust = header
|
2017-04-01 13:45:50 +00:00
|
|
|
assert self.magic == b'TRZV'
|
2017-02-09 17:14:10 +00:00
|
|
|
assert self.vsig_m > 0 and self.vsig_m <= self.vsig_n
|
|
|
|
assert self.vsig_n > 0 and self.vsig_n <= 8
|
2017-10-05 15:31:05 +00:00
|
|
|
p = 32
|
2017-02-09 17:14:10 +00:00
|
|
|
self.vpub = []
|
|
|
|
for _ in range(self.vsig_n):
|
|
|
|
self.vpub.append(data[p:p + 32])
|
|
|
|
p += 32
|
|
|
|
self.vstr_len = data[p]
|
|
|
|
p += 1
|
|
|
|
self.vstr = data[p:p + self.vstr_len]
|
|
|
|
p += self.vstr_len
|
2017-04-01 13:45:50 +00:00
|
|
|
vstr_pad = -p & 3
|
|
|
|
p += vstr_pad
|
|
|
|
self.vimg_len = len(data) - 65 - p
|
2017-02-09 17:14:10 +00:00
|
|
|
self.vimg = data[p:p + self.vimg_len]
|
|
|
|
p += self.vimg_len
|
2017-04-01 00:32:05 +00:00
|
|
|
self.sigmask = data[p]
|
2017-02-09 17:14:10 +00:00
|
|
|
p += 1
|
2017-09-05 21:15:47 +00:00
|
|
|
self.sig = data[p:p + 64]
|
2017-10-05 15:31:05 +00:00
|
|
|
assert len(data) == 4 + 4 + 4 + 1 + 1 + 1 + 1 + 1 + 15 + \
|
2017-02-09 17:14:10 +00:00
|
|
|
32 * len(self.vpub) + \
|
2017-04-01 13:45:50 +00:00
|
|
|
1 + self.vstr_len + vstr_pad + \
|
|
|
|
self.vimg_len + \
|
2017-02-09 17:14:10 +00:00
|
|
|
1 + 64
|
2017-02-09 15:26:15 +00:00
|
|
|
|
|
|
|
def print(self):
|
2017-02-09 17:14:10 +00:00
|
|
|
print('TREZOR Vendor Header')
|
|
|
|
print(' * magic :', self.magic.decode('ascii'))
|
|
|
|
print(' * hdrlen :', self.hdrlen)
|
|
|
|
print(' * expiry :', self.expiry)
|
|
|
|
print(' * version : %d.%d' % (self.vmajor, self.vminor))
|
|
|
|
print(' * scheme : %d out of %d' % (self.vsig_m, self.vsig_n))
|
2017-10-05 15:31:05 +00:00
|
|
|
print(' * trust :', self.vtrust)
|
2017-02-09 17:14:10 +00:00
|
|
|
for i in range(self.vsig_n):
|
|
|
|
print(' * vpub #%d :' % (i + 1), binascii.hexlify(self.vpub[i]).decode('ascii'))
|
2017-04-02 00:25:55 +00:00
|
|
|
print(' * vstr :', self.vstr.decode('ascii'))
|
|
|
|
print(' * vimg : (%d bytes)' % len(self.vimg))
|
2017-04-06 16:57:51 +00:00
|
|
|
print(' * sigmask :', format_sigmask(self.sigmask))
|
2017-04-02 00:25:55 +00:00
|
|
|
print(' * sig :', binascii.hexlify(self.sig).decode('ascii'))
|
2017-02-09 17:14:10 +00:00
|
|
|
|
2017-03-30 20:58:00 +00:00
|
|
|
def serialize_header(self, sig=True):
|
2017-10-05 15:31:05 +00:00
|
|
|
header = struct.pack('<4sIIBBBBB',
|
2017-09-05 21:15:47 +00:00
|
|
|
self.magic, self.hdrlen, self.expiry,
|
|
|
|
self.vmajor, self.vminor,
|
2017-10-05 15:31:05 +00:00
|
|
|
self.vsig_m, self.vsig_n, self.vtrust)
|
|
|
|
header += 15 * b'\x00'
|
2017-02-09 17:14:10 +00:00
|
|
|
for i in range(self.vsig_n):
|
|
|
|
header += self.vpub[i]
|
|
|
|
header += struct.pack('<B', self.vstr_len) + self.vstr
|
2017-09-05 21:15:47 +00:00
|
|
|
header += (-len(header) & 3) * b'\x00' # vstr_pad
|
2017-04-02 00:25:55 +00:00
|
|
|
header += self.vimg
|
2017-02-09 17:14:10 +00:00
|
|
|
if sig:
|
2017-04-01 00:32:05 +00:00
|
|
|
header += struct.pack('<B64s', self.sigmask, self.sig)
|
2017-02-09 17:14:10 +00:00
|
|
|
else:
|
|
|
|
header += 65 * b'\x00'
|
2017-02-17 16:11:34 +00:00
|
|
|
assert len(header) == self.hdrlen
|
2017-02-09 17:14:10 +00:00
|
|
|
return header
|
2017-02-09 15:26:15 +00:00
|
|
|
|
2017-10-01 14:26:51 +00:00
|
|
|
def sign(self, sigmask, seckeys):
|
2017-10-01 15:46:58 +00:00
|
|
|
# check whether provided arguments match vsig_m/vsig_n
|
|
|
|
if len(seckeys) != self.vsig_m:
|
|
|
|
raise Exception('invalid number of signatures (vsig_m expected %d, got %d)' % (self.vsig_m, len(seckeys)))
|
|
|
|
if sigmask >= (1 << self.vsig_n):
|
|
|
|
raise Exception('signature index is higher than vsig_n (%d)' % self.vsig_n)
|
|
|
|
if bin(sigmask).count('1') != self.vsig_m:
|
|
|
|
raise Exception('invalid number of indexes (vsig_m expected %d, got %d)' % (self.vsig_m, bin(sigmask).count('1')))
|
|
|
|
# sign
|
2017-03-30 20:58:00 +00:00
|
|
|
header = self.serialize_header(sig=False)
|
2017-04-08 16:23:08 +00:00
|
|
|
self.sigmask = sigmask
|
2017-10-01 14:26:51 +00:00
|
|
|
self.sig = sign_data(seckeys, header)
|
2017-02-09 17:14:10 +00:00
|
|
|
|
|
|
|
def write(self, filename):
|
|
|
|
with open(filename, 'wb') as f:
|
2017-03-30 20:58:00 +00:00
|
|
|
f.write(self.serialize_header())
|
2017-02-09 15:26:15 +00:00
|
|
|
|
|
|
|
|
|
|
|
def binopen(filename):
|
|
|
|
data = open(filename, 'rb').read()
|
2017-08-07 09:50:12 +00:00
|
|
|
data = bytearray(data) # python2/3 compatibility
|
2017-02-09 15:26:15 +00:00
|
|
|
magic = data[:4]
|
2017-04-10 17:24:21 +00:00
|
|
|
if magic == b'TRZB':
|
|
|
|
return BootloaderImage(data)
|
2017-04-01 13:45:50 +00:00
|
|
|
if magic == b'TRZV':
|
|
|
|
vheader = VendorHeader(data)
|
|
|
|
if len(data) == vheader.hdrlen:
|
|
|
|
return vheader
|
|
|
|
subdata = data[vheader.hdrlen:]
|
|
|
|
if subdata[:4] == b'TRZF':
|
|
|
|
return FirmwareImage(data, vheader.hdrlen)
|
2017-02-09 15:26:15 +00:00
|
|
|
if magic == b'TRZF':
|
2017-04-01 13:45:50 +00:00
|
|
|
return FirmwareImage(data, 0)
|
2017-02-09 15:26:15 +00:00
|
|
|
raise Exception('Unknown file format')
|
|
|
|
|
2017-09-05 21:15:47 +00:00
|
|
|
|
2017-02-09 15:26:15 +00:00
|
|
|
def main():
|
|
|
|
if len(sys.argv) < 2:
|
2017-04-08 16:23:08 +00:00
|
|
|
print('Usage: binctl file.bin [-s index seckey]')
|
2017-02-09 15:26:15 +00:00
|
|
|
return 1
|
|
|
|
fn = sys.argv[1]
|
|
|
|
sign = len(sys.argv) > 2 and sys.argv[2] == '-s'
|
|
|
|
b = binopen(fn)
|
|
|
|
if sign:
|
2017-10-01 14:26:51 +00:00
|
|
|
sigmask = 0
|
|
|
|
if ':' in sys.argv[3]:
|
|
|
|
for idx in sys.argv[3].split(':'):
|
2017-10-01 15:46:58 +00:00
|
|
|
sigmask |= 1 << (int(idx) - 1)
|
2017-10-01 14:26:51 +00:00
|
|
|
else:
|
|
|
|
sigmask = 1 << (int(sys.argv[3]) - 1)
|
|
|
|
if ':' in sys.argv[4]:
|
2017-10-04 07:59:04 +00:00
|
|
|
seckeys = sys.argv[4].split(':')
|
|
|
|
for i in range(len(seckeys)):
|
|
|
|
if seckeys[i] != 'trezor':
|
|
|
|
seckeys[i] = binascii.unhexlify(seckeys[i])
|
2017-10-01 14:26:51 +00:00
|
|
|
else:
|
|
|
|
seckeys = [binascii.unhexlify(sys.argv[4])]
|
|
|
|
b.sign(sigmask, seckeys)
|
2017-02-09 15:26:15 +00:00
|
|
|
print()
|
|
|
|
b.write(fn)
|
2017-04-08 16:23:08 +00:00
|
|
|
b.print()
|
2017-02-09 15:26:15 +00:00
|
|
|
|
|
|
|
|
|
|
|
if __name__ == '__main__':
|
|
|
|
main()
|